Skip to content

Black Hat 2026 AI Security Trends: Andy Ellis Finds an Industry Better at Finding Risk Than Fixing It

Andy Ellis' analysis of all 450 Black Hat USA 2026 exhibitors found AI has become cybersecurity's dominant message, while governance tools now outnumber technologies focused on directly preventing attacks.

Full coverage of Hacker Summer Camp:

Hacker Summer Camp 2026: Complete Black Hat, BSidesLV, Ai4 & DEF CON Coverage
The CYBR.SEC.Media crew is in Las Vegas to bring you all the insights coming from this week’s proceedings.
Hacker Summer Camp, AI Vishing Targets Wall Street, Packet Protectors and Multi-State Attacks on Water Utilities
All the news and analysis of the past week!

If Black Hat USA 2026 proved anything, it's that cybersecurity has officially entered the AI era.

That's one of the headline conclusions from a new report by Andy Ellis, former Akamai CSO and CEO and Principal of Duha, who spent three days walking the Business Hall, documenting the messaging, themes and positioning of all 450 exhibitors.

Here's the full report:

State of Security Vendors: Blackhat 2026 - Duha
We have entered into an AI world. While nearly half of Blackhat booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse. At the same time, there’s a clear

The numbers tell part of the story. AI appeared in the messaging of 199 vendors, while another 104 referenced agents or agentic technology. Altogether, 235 exhibitors—more than half the show floor — marketed AI or autonomous agents as part of their value proposition.

But Ellis argues the industry's transformation runs deeper than simply adding "AI-powered" to booth graphics.

"We have entered into an AI world," he writes, noting that even companies that didn't explicitly mention AI often competed in markets fundamentally reshaped by it.

The report is based on approximately 12 hours of observations across three days, with Ellis documenting booth messaging before validating his findings against vendor websites, prior conference datasets and conversations with exhibitors.

Cybersecurity's AI conversation has moved beyond copilots

One of the report's more notable findings is how quickly vendors have shifted beyond talking about AI assistants.

Ellis observed companies increasingly promoting fleets of AI agents rather than individual assistants. Others focused on governing agents developed by third parties, while another emerging segment concentrated on securing enterprise AI agents themselves.

He also notes that many companies previously known for SaaS Security Posture Management (SSPM) have repositioned themselves around AI governance, reflecting how rapidly the market is evolving.

The implication is significant. AI is no longer simply another feature layered onto existing cybersecurity products. It is beginning to reshape entire product categories.

Governance, not prevention, now dominates the market

Perhaps the report's most revealing finding has nothing to do with AI.

Ellis organizes vendors by the environments they protect rather than by marketing language. Under that framework, Governance has become the largest category at Black Hat, with 80 exhibitors.

His Governance category encompasses compliance management, third-party risk management, Continuous Threat and Exposure Management (CTEM), unified threat intelligence and offensive security—all disciplines focused primarily on helping organizations understand their risk.

Applications followed with 67 exhibitors, while Security Operations ranked third with 55. AI itself accounted for 39 companies focused specifically on AI governance, AI observability and AI safety rather than simply applying AI to existing security workflows.

The breakdown reinforces one of Ellis' central observations: cybersecurity has become exceptionally good at producing technologies that identify, categorize and prioritize risk.

Whether it is becoming equally good at helping organizations eliminate that risk is another matter.

AI may be accelerating an old cybersecurity problem

Ellis describes today's cybersecurity landscape as falling into three broad categories:

  • Products that tell organizations how bad things are.
  • Products that stop attackers.
  • Products that prevent problems from occurring.

His conclusion is difficult to ignore.

"The tools that merely tell you how bad things are seem to be frustratingly plentiful."

It's an observation that lands at a time when security teams are already wrestling with vulnerability backlogs, exposure management platforms, sprawling attack path analyses and AI-powered prioritization engines.

Artificial intelligence is making it dramatically easier to discover risk. The report raises a larger question about whether the industry's ability to remediate that risk is advancing at the same pace.

Identity is becoming an AI security problem

The report also highlights identity as one of the markets being transformed most rapidly by AI.

Ellis writes that longstanding identity challenges have "exploded with the rise of agents using humans' identities." His Identity category now spans IAM, IGA, MFA, Identity Threat Detection and Response and non-human identities, reflecting the growing reality that AI systems increasingly operate using delegated human credentials.

At the same time, Ellis deliberately limits his AI category to vendors securing AI itself—through governance, observability or safety—rather than including every company that has embedded AI into an existing product.

That distinction suggests AI security is rapidly emerging as a market of its own rather than simply another feature set.

Marketing still struggles to explain cybersecurity

Ellis' report also revisits a theme that has appeared in his previous conference analyses: too many vendors still fail to clearly communicate what they do.

He found that 57 exhibitors lacked enough visible messaging for him to determine their purpose simply by walking past the booth.

He also identified 39 heavily themed booths, seven of which contained little or no visible product messaging.

The findings reinforce his long-running criticism that many conference booths optimize for attracting badge scans rather than educating prospective customers. Ellis argues exhibition marketing often incentivizes spectacle over clarity, turning booths into experiences designed to collect contact information instead of helping practitioners understand what a company actually offers.

Black Hat continues to develop its own identity

The report also suggests Black Hat's exhibition hall continues to diverge from RSA Conference.

Ellis estimates the Business Hall added roughly 100 booths compared to last year, driven in part by the expansion of the AI zone. He also notes that roughly half of Black Hat exhibitors did not exhibit at RSA Conference, indicating that the two events increasingly attract different mixes of vendors rather than serving as mirror images of one another.

An industry entering its next phase

Ellis' report ultimately argues that cybersecurity has entered a new stage of its AI evolution.

The conversation has moved beyond copilots toward autonomous agents, AI governance and securing machine identities. Entire market segments are repositioning themselves around AI, while established categories like identity and security operations are expanding to accommodate autonomous systems.

At the same time, his findings suggest the industry's oldest challenge remains unresolved. As AI enables organizations to identify more vulnerabilities, exposures and operational risk than ever before, security vendors may increasingly be judged not by how effectively they surface those problems, but by how effectively they help customers solve them.

If Black Hat 2026 offered a glimpse of where cybersecurity is headed, Ellis' report suggests the next competitive battleground won't simply be building smarter AI. It will be proving that AI can reduce risk rather than just measure it.

HOU.SEC.CON CTA

Latest